Infopop · Infopop Ultimate Bulletin Board · CVE-2022-25091
**Name of the Vulnerable Software and Affected Versions**
Infopop Ultimate Bulletin Board versions up to 5.47a
**Description**
The issue allows all messages posted inside private forums to be disclosed by unauthenticated users via the `quote reply` feature.
**Recommendations**
For Infopop Ultimate Bulletin Board versions up to 5.47a, consider disabling the quote reply feature until a patch is available to prevent unauthorized disclosure of private forum messages.